🤖 AI Summary
This study addresses the inability of existing black-box malware detectors to provide fine-grained localization of malicious logic origins and specific behaviors. To this end, we propose a behavior-centric analysis framework that constructs structured behavior graphs through context-sensitive backward API slicing and call chain reconstruction. The method integrates Transformers to capture instruction semantics with Graph Neural Networks (GNNs) to model structural dependencies, leveraging attention-based attribution mechanisms to achieve interpretable, precise classification and localization. Experimental results demonstrate that the proposed framework achieves superior performance across standard evaluation metrics and behavioral coverage. By overcoming the inherent limitations of traditional black-box approaches, this work enables high-accuracy malware classification alongside fine-grained localization of malicious logic.
📝 Abstract
Effective malware analysis requires understanding not only whether a program is malicious, but also which behaviors it exhibits and where those behaviors originate in the code. Existing machine-learning-based malware detectors largely operate as black boxes, providing limited insight into the malicious logic responsible for their decisions. This paper addresses malicious behavior localization and classification at the basic-block level. We propose a behavior-centric analysis framework that decomposes malware samples into behaviors and systematically links these behaviors to their originating code regions. Using context-sensitive backward slicing from security-relevant system API calls, we reconstruct control- and data-dependency chains and represent each behavior as a structured graph of related basic blocks. A Transformer-based model captures instruction-level semantics, while a Graph Neural Network models structural dependencies within behavior graphs. The resulting representations are fused to enable accurate and interpretable classification, with attention-based attribution identifying code regions responsible for malicious behaviors. We evaluate our approach using standard classification metrics and a behavior coverage metric that measures the detection of manually labeled malicious behaviors. Our results demonstrate that the proposed framework achieves accurate malware classification while providing fine-grained, behavior-aware localization of malicious logic.